Hello, 

I would like to be notified when I receive X times a special log (security 
logs). 
Today, each time someone enters a wrong password, I receive this log from ssh. 


pam_unix(sshd:auth): check pass; user unknown 

It's not interesting but in case of X failures. 

So, Is there a way to count logs and proceed an action when the counter reach a 
specified number ? 

Regards, 
Nicolas Even 
_______________________________________________
rsyslog mailing list
http://lists.adiscon.net/mailman/listinfo/rsyslog
http://www.rsyslog.com

Reply via email to